Description
A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Published: 2023-05-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-32059 A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
History

Mon, 27 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Uni Cloud Key Gen2 Cloud Key Gen2 Plus Ubiquiti Networks Unifi Dream Machine Ubiquiti Networks Unifi Dream Machine Professional Ubiquiti Networks Unifi Dream Machine Se Unifi Dream Router Unifi Os Unifi Protect Network Video Recorder Unifi Protect Network Video Recorder Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-01-27T16:44:43.627Z

Reserved: 2023-03-15T00:00:00.000Z

Link: CVE-2023-28361

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:24.989Z

cve-icon NVD

Status : Modified

Published: 2023-05-11T22:15:10.187

Modified: 2025-01-27T17:15:12.240

Link: CVE-2023-28361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses